There is actually a lot more to this: a lot of people in the it sec crowd have been saying for many years that this habit of the gibberish passwords with symbols capitals and whatnot is actually a net deficit in security. Mostly because for the longest time people had to mostly remember all passwords and the policies for rotation were to aggressive (which lead to “lazy” changes). Nowadays unfortunately we still have people that inherited this thinking and still enforce this, but you also see a lot of people understanding that pass phrases are a lot better (of course should not be a predictable phrase like good morning, but it is possible to make it much better with way less effort)
There is actually a lot more to this: a lot of people in the it sec crowd have been saying for many years that this habit of the gibberish passwords with symbols capitals and whatnot is actually a net deficit in security. Mostly because for the longest time people had to mostly remember all passwords and the policies for rotation were to aggressive (which lead to “lazy” changes). Nowadays unfortunately we still have people that inherited this thinking and still enforce this, but you also see a lot of people understanding that pass phrases are a lot better (of course should not be a predictable phrase like good morning, but it is possible to make it much better with way less effort)
Correct horse battery staple
More that just “… a lot of people…” NIST themselves published real research backing this up over a decade ago.